Re: BUG #19752: GROUP BY on a constant and a cast to a length-limited array type crashes the server while planning

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: mertkul669(at)gmail(dot)com
Cc: pgsql-bugs(at)lists(dot)postgresql(dot)org, Richard Guo <guofenglinux(at)gmail(dot)com>
Subject: Re: BUG #19752: GROUP BY on a constant and a cast to a length-limited array type crashes the server while planning
Date: 2026-10-08 19:31:48
Message-ID: 2530849.1791487908@sss.pgh.pa.us
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-bugs

PG Bug reporting form <noreply(at)postgresql(dot)org> writes:
> I found a planner crash (SIGSEGV) in PostgreSQL 18 with the following
> query:

> SELECT ARRAY[]::varchar(500)[]
> GROUP BY CAST('true' AS boolean);

> Cause
> For ARRAY[]::varchar(500)[], the parser builds an ArrayCoerceExpr whose
> elemexpr is a per-element template:
> varchar(CaseTestExpr, 500, true)
> where the final "true" is the internal isExplicit flag.
> substitute_grouped_columns_mutator() in parse_agg.c replaces any
> subexpression that equal()s a GROUP BY expression with a Var referencing
> the RTE_GROUP RTE. It also descends into elemexpr. The GROUP BY
> expression is Const(bool, true), and the internal isExplicit flag is also
> Const(bool, true), so the flag is wrongly replaced by a Var. (Dumping
> elemexpr at the point of failure on 18.4 shows the third argument is a
> VAR rather than a CONST.)

Yeah, that's nasty, and what's nastier is that even non-crash cases
might result in seriously wrong answers. We shouldn't be replacing
constant subexpressions by group Vars ever. I'm inclined to think
that GROUP BY items should not be candidates for this
search-and-replace unless they contain at least one level-zero Var.
But maybe that's too simplistic?

regards, tom lane

In response to

Responses

Browse pgsql-bugs by date

  From Date Subject
Next Message Andrey Rachitskiy 2026-10-08 19:48:05 Re: BUG #19752: GROUP BY on a constant and a cast to a length-limited array type crashes the server while planning
Previous Message Andrey Borodin 2026-10-08 18:53:17 Re: Do we want to solve reload/config races more generally? (was: Postmaster crashes on SIGHUP when oauth_validator_libraries holds only whitespace)